parallel-comparator-200 打开是c语言的源代码 分析main函数,注意到其中的比较函数highly_optimized_parallel_comparsion是关键
int main()
{
char *user_string = (char *)calloc(FLAG_LEN+1, sizeof(char));
fgets(user_string, FLAG_LEN+1, stdin);
int is_ok = highly_optimized_parallel_comparsion(user_string);
if (is_ok)
printf("You win!\n");
else
printf("Wrong!\n");
return 0;
}
int highly_optimized_parallel_comparsion(char *user_string)
{
int initialization_number;
int i;
char generated_string[FLAG_LEN + 1];
generated_string[FLAG_LEN] = '\0';
while ((initialization_number = random()) >= 64);
int first_letter;
first_letter = (initialization_number % 26) + 97;
首先可以确定first_letter的范围是【97,122】 接下来是三个for循环 第一个for循环
pthread_t thread[FLAG_LEN];
char differences[FLAG_LEN] = {0, 9, -9, -1, 13, -13, -4, -11, -9, -1, -7, 6, -13, 13, 3, 9, -13, -11, 6, -7};
char *arguments[20];
for (i = 0; i < FLAG_LEN; i++) {
arguments[i] = (char *)malloc(3*sizeof(char));
arguments[i][0] = first_letter;
arguments[i][1] = differences[i];
arguments[i][2] = user_string[i];
pthread_create((pthread_t*)(thread+i), NULL, checking, arguments[i]);
}
总结一下是(first_letter+differences[i])^user_string[i]=result 第二个for循环
void *result;
int just_a_string[FLAG_LEN] = {115, 116, 114, 97, 110, 103, 101, 95, 115, 116, 114, 105, 110, 103, 95, 105, 116, 95, 105, 115};
for (i = 0; i < FLAG_LEN; i++) {
pthread_join(*(thread+i), &result);
generated_string[i] = *(char *)result + just_a_string[i];
free(result);
free(arguments[i]);
}
总结一下是generated_string[i]=result+just_a_string[i] 第三个for循环
int is_ok = 1;
for (i = 0; i < FLAG_LEN; i++) {
if (generated_string[i] != just_a_string[i])
return 0;
得出返回的result必须为0 即(first_letter+differences[i])^user_string[i]=0 根据(a+b)^c=0可以推出 (a+b)^0=c 即user_string[i]=(first_letter+differences[i])^0 接下来写代码
differences= [0, 9, -9, -1, 13, -13, -4, -11, -9, -1, -7, 6, -13, 13, 3, 9, -13, -11, 6, -7];
first_letter=97
for j in range(26):
result=''
first_letter+=1
for i in range(len(differences)):
result+=chr(first_letter+differences[i]^0)
print(result,"--",first_letter+differences[i])
得到flag:lucky_hacker_you_are
|